5-11
Cisco Wireless LAN Controller Configuration Guide
OL-9141-03
Chapter 5 Configuring Security Solutions
Configuring Access Control Lists
•
AH
—Authentication Header
•
GRE
—Generic Routing Encapsulation
•
IP
—Internet Protocol
•
Eth Over IP
—Ethernet-over-Internet Protocol
•
OSPF
—Open Shortest Path First
•
Other
—Any other Internet Assigned Numbers Authority (IANA) protocol
(http://www.iana.org)
e.
If you chose TCP or UDP in the previous step, two additional parameters appear: Source Port and
Destination Port. These parameters enable you to choose a specific source port and destination
protocol or port ranges. The port options are used by applications that send and receive data to and
from the networking stack. Some ports are designated for certain applications such as telnet, ssh,
http, ICMP, and so on.
f.
From the DSCP drop-down box, choose one of these options to specify the differentiated services
code point (DSCP) value of this ACL. DSCP is a packet header code that can be used to define the
quality of service across the Internet.
•
Any
—Any DSCP (This is the default value.)
•
Specific
—A specific DSCP from 0 to 63, which you enter in the DSCP edit box
g.
From the Direction drop-down box, choose one of these options to specify the direction of the traffic
to which this ACL applies:
•
Any
—Any direction (This is the default value.)
•
Inbound
—From the client
•
Outbound
—To the client
h.
From the Action drop-down box, choose
Deny
to cause this ACL to block packets or
Permit
to cause
this ACL to allow packets. The default value is Deny.
i.
Click
Apply
to commit your changes. The Access Control Lists > Edit page reappears, showing the
rules for this ACL. See
Figure 5-5
.
Figure 5-5
Access Control Lists > Edit Page
This page also enables you to edit or remove any of the rules.
j.
Repeat this procedure to add any additional rules for this ACL.
Step 7
Click
Save
Configuration
to save your changes.